CFPB Turns Its Attention to Data Security

On August 11, the Consumer Financial Protection Bureau published a circular, answering the question “Can entities violate the prohibition on unfair acts or practices in the Consumer Financial Protection Act when they have insufficient data protection or information security?” with a resounding “yes.” Specifically, the CFPB pointed to three practices—inadequate authorization, poor password management, and lax software update policies—as examples of data security practices that would likely cause substantial unavoidable injury to consumers without a countervailing benefit and that could trigger liability for financial institutions and/or their service providers.
